220-1102 Security Practice Question
A company policy requires that all company-issued smartphones can be remotely wiped in case of loss or theft. Which of the following should a technician enable on the devices to meet this requirement?
⚠ Common exam trap
A common mix-up: candidates confuse 'remote lock' with 'remote wipe' because both are security features, but the question explicitly requires data deletion, not just access restriction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable a Mobile Device Management (MDM) profile that supports remote wipe
Mobile Device Management (MDM) profiles include a remote wipe capability that allows administrators to send a command to erase all data on a lost or stolen device. This directly satisfies the company policy requirement for remote wipe, as MDM platforms use protocols like OMA-DM to push a factory reset command to the device, ensuring data is irrecoverably removed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Full device encryption
Why it's wrong here
Full device encryption protects data at rest by transforming it into an unreadable format without the correct decryption key, usually tied to the device passcode. While this thwarts casual physical access, it does not actively erase data when the device is lost or an employee leaves, and if the passcode is weak, compromised, or derived through other means, the data can still be decrypted. Encryption is a valuable baseline control but does not satisfy a policy that mandates remote data removal.
- ✗
Remote lock
Why it's wrong here
Remote lock only momentarily blocks access to the device by requiring a passcode or PIN. It does not delete any data, so sensitive files, emails, or credentials remain on the storage medium and can later be recovered using forensic tools or if the device is unlocked by an attacker. This makes it a containment measure, not a data-erasure solution, and it fails the policy's requirement to remove company data from a lost or stolen device.
- ✓
Enable a Mobile Device Management (MDM) profile that supports remote wipe
Why this is correct
Enabling an MDM profile with remote wipe capability is the only option that allows an administrator to remotely issue an erase command to the device, triggering a secure wipe that destroys both the encryption keys and the data they protect. The wipe process typically resets the device to factory state, rendering all corporate and personal data unrecoverable. This directly fulfills the company policy's requirement because the administrator can execute the wipe from a management console upon loss or termination, without needing physical access to the device.
- ✗
Enable automatic app updates
Why it's wrong here
Automatic app updates ensure that known vulnerabilities in installed applications are patched promptly, which reduces the risk of malware infection or unauthorized access. However, automatic updates have no mechanism to erase data remotely; they only modify application code on the device. Therefore, this option does not address the policy's data-removal requirement and cannot be used to respond to a lost, stolen, or offboarded device.
Go deeper
Related to this question
Learn chapter
Software Patch Management
Key term
MDM
MDM stands for Mobile Device Management, a technology that allows IT administrators to securely manage, monitor, and enforce policies on mobile devices like smartphones and tablets from a central console.
Key term
Mobile device management
Mobile device management (MDM) is a security solution that allows IT administrators to enroll, configure, monitor, and enforce policies on smartphones, tablets, and other mobile devices used in an organization.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.